Sceawere
Vulnerability Detail
CVE-2026-105135UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Code Injection in MindSearch Planner
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 2h ago
- Vendor
- InternLM
- Product
- MindSearch
- Attack Type
- Code Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-04T07:16:33.693Z",
"pubdate": "2026-10-04T07:16:33.693Z",
"executiveSummary": "A critical code injection vulnerability exists within the Planner Agent of InternLM MindSearch 0.1.0.\nThe vulnerability resides in the ExecutionAction.run function located in mindsearch/agent/graph.py.\nImproper neutralization of user-supplied inputs allows a remote, unauthenticated attacker to execute arbitrary code within the host environment.\nSuccessful exploitation leads to a complete compromise of the application's runtime context, potentially granting the attacker unauthorized access to underlying system resources, data exfiltration capabilities, or persistence mechanisms.\nThe lack of vendor response exacerbates the risk, as no official patches are currently available.\nOrganizations relying on this version of the Planner Agent are at high risk, as the exploit is publicly disclosed and readily available for malicious exploitation.",
"technicalDetails": "The vulnerability is a direct result of an injection flaw within the ExecutionAction.run method of the Planner Agent in InternLM MindSearch 0.1.0, specifically located in mindsearch/agent/graph.py.\nThe root cause is the insecure handling of the 'inputs' argument, which is processed by the function without sufficient sanitization or validation before being utilized in an execution context.\nWhen the Planner Agent processes a request, it invokes ExecutionAction.run. If the 'inputs' argument contains malicious, crafted sequences, the application may inadvertently treat this data as executable code or commands rather than passive input.\nThe attack flow begins with a remote request sent to the MindSearch service. The attacker crafts a payload designed to break out of the intended logic boundary of the ExecutionAction.run function. By embedding shell commands or language-specific code execution primitives into the 'inputs' parameter, the attacker forces the system to interpret and execute their payload.\nBecause the agent architecture is designed to perform operations based on these inputs, it inherently possesses the privileges necessary to interact with the environment. Consequently, the injected code executes with the same privilege level as the MindSearch process itself.\nThe vulnerability does not require prior authentication, making it particularly dangerous in deployments exposed to the internet or untrusted internal networks. The attacker's payload can range from simple reconnaissance—such as environment variable exfiltration—to full-scale system exploitation, including the installation of backdoors or the deployment of additional malicious modules within the host OS.\nAs this is a code injection vector, the payload behavior depends heavily on the underlying execution environment (e.g., Python exec/eval context). By leveraging common techniques, an attacker can manipulate the internal execution state to pivot within the host system, effectively bypassing application-level security controls."
}